VDB
Sign up
HIGH7.5

GHSA-39fp-mqmm-gxj6

CodeIgniter4 DoS Vulnerability

Quick fix

GHSA-39fp-mqmm-gxj6 — codeigniter4/framework: upgrade to the fixed version with the command below.

composer require codeigniter4/framework:^4.4.7

Details

### Impact A vulnerability was found in the Language class that allowed DoS attacks. This vulnerability can be exploited by an attacker to consume a large amount of memory on the server.

### Patches Upgrade to v4.4.7 or later. See [upgrading guide](https://codeigniter4.github.io/userguide/installation/upgrade_447.html).

### Workarounds - Disabling Auto Routing prevents a known attack vector in the framework. - Do not pass invalid values to the `lang()` function or `Language` class.

### References - https://codeigniter4.github.io/userguide/outgoing/localization.html#language-localization - https://codeigniter4.github.io/userguide/general/common_functions.html#lang

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/codeigniter4/framework
Introduced in: 0Fixed in: 4.4.7
Fixcomposer require codeigniter4/framework:^4.4.7

References